|
266591
|
7.8 |
HIGH
Local
|
canonical
|
ubuntu_linux
|
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-0727
|
2024-11-21 11:42 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266592
|
9.8 |
CRITICAL
Network
|
apache
|
tomee
|
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-0779
|
2024-11-21 11:42 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266593
|
6.1 |
MEDIUM
Network
|
zahmit_design
|
connections_business_directory_plugin
|
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2016-0770
|
2024-11-21 11:42 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266594
|
6.1 |
MEDIUM
Network
|
rsa
|
web_threat_detection
|
EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by …
|
CWE-79
Cross-site Scripting
|
CVE-2016-0919
|
2024-11-21 11:42 |
2017-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266595
|
6.4 |
MEDIUM
Network
|
emc
|
powerpath_virtual_appliance
|
EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploite…
|
CWE-200
Information Exposure
|
CVE-2016-0890
|
2024-11-21 11:42 |
2017-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266596
|
8.8 |
HIGH
Network
|
elfden
|
eshop_plugin
|
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote…
|
CWE-89
SQL Injection
|
CVE-2016-0769
|
2024-11-21 11:42 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266597
|
6.1 |
MEDIUM
Network
|
elfden
|
eshop_plugin
|
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2016-0765
|
2024-11-21 11:42 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266598
|
9.8 |
CRITICAL
Network
|
mailcwp_project
|
mailcwp
|
Mailcwp remote file upload vulnerability incomplete fix v1.100
|
CWE-77 CWE-284
Command Injection Improper Access Control
|
CVE-2016-1000156
|
2024-11-21 11:42 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266599
|
8.4 |
HIGH
Local
|
emc
|
avamar_data_store avamar_server_virtual_edition
|
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to potentially be compromised by malicious users.
|
CWE-20
Improper Input Validation
|
CVE-2016-0909
|
2024-11-21 11:42 |
2016-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266600
|
7.2 |
HIGH
Network
|
huge-it
|
slider
|
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
|
CWE-89
SQL Injection
|
CVE-2016-1000122
|
2024-11-21 11:42 |
2016-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|